cbcvebase.
CVE-2019-6188
published 2019-11-12

CVE-2019-6188: The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which…

PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.32%
67.6th percentile
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.

Affected

12 ranges
VendorProductVersion rangeFixed in
lenovothinkpad_helix_firmware< gfet65wwgfet65ww
lenovothinkpad_s531_firmware< gket46wwgket46ww
lenovothinkpad_t440_firmware< gjeta3wwgjeta3ww
lenovothinkpad_t440p_firmware< gleta0wwgleta0ww
lenovothinkpad_t440s_firmware< gjeta3wwgjeta3ww
lenovothinkpad_t460p>= unspecified < R07ET90WR07ET90W
lenovothinkpad_t470p>= unspecified < R0FET50WR0FET50W
lenovothinkpad_t540p_firmware< gmet89wwgmet89ww
lenovothinkpad_w540_firmware< gnet92wwgnet92ww
lenovothinkpad_w541_firmware< gnet92wwgnet92ww
lenovothinkpad_x240_firmware< giet98wwgiet98ww
lenovothinkpad_x240s_firmware< giet98wwgiet98ww

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.